AZ-104 Implement and Manage Virtual Networking Practice Question
Traffic from Subnet-App to the internet is being routed through a virtual appliance unexpectedly. You need to identify which route is being applied to the network interface of VM-App01. Which Azure feature should you use?
⚠ Common exam trap
Watch out — candidates often confuse NSG flow logs (which show traffic filtering) with effective routes (which show routing decisions), leading them to pick NSG flow logs when the question is about path selection rather than security rule evaluation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Effective routes for the network interface
Effective routes for the network interface (NIC) shows the actual routes applied to a specific VM's NIC after evaluating all route tables, virtual network gateway routes, and BGP routes. Since traffic from Subnet-App to the internet is unexpectedly going through a virtual appliance, you need to see which route (e.g., a user-defined route with next hop type VirtualAppliance or VirtualNetworkGateway) is being selected based on the longest prefix match. This tool directly displays the effective next hop for each destination prefix, allowing you to identify the misconfigured route causing the traffic to be redirected.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Effective routes for the network interface
Why this is correct
Effective routes for a network interface are the authoritative, data-plane view of the actual routing decisions applied to a VM's NIC. They combine Azure system routes, user-defined routes, and BGP routes, and display the selected next hop for each address prefix. To confirm that traffic from the app subnet to the internet uses a specific next hop (e.g., Internet, VPN gateway, or NVA), this blade shows the computed route that is actually used, not just a configured route table.
- ✗
NSG flow logs
Why it's wrong here
NSG flow logs capture the outcomes of IP traffic through a network security group, logging whether each flow was allowed or denied based on the security rules. They do not contain any routing information, such as the next hop or the effective route prefix, because routing is evaluated before NSG rules in the Azure network stack. Therefore, NSG flow logs can show that internet traffic is succeeding or being blocked, but they cannot reveal whether that traffic is being sent through a particular route or gateway.
When this WOULD be correct
When you need to analyze network traffic patterns, detect anomalies, or troubleshoot connectivity issues related to NSG rules, such as identifying denied or allowed traffic between VMs.
- ✗
Azure Policy compliance
Why it's wrong here
Azure Policy compliance evaluates whether Azure resources meet governance rules, such as requiring a specific route table on a subnet or prohibiting certain NSG rules. It is a control-plane auditing mechanism that reports policy evaluation results, not a diagnostic tool that reveals data-plane routing behavior. Even a policy that detects a missing UDR would not show the effective route entries actually applied to a network interface, so it cannot answer where traffic is currently being routed.
When this WOULD be correct
An exam question asks: 'You need to ensure that all network interfaces in a subscription have a specific tag. Which Azure feature should you use to audit compliance?' In that case, Azure Policy compliance would be correct.
- ✗
The subscription activity log
Why it's wrong here
The subscription activity log records only control-plane events, including create, update, and delete operations on Azure resources like route tables, subnets, and virtual networks. It does not capture data-plane traffic flows or the runtime route entries that are derived for a specific NIC. While associating a route table might appear as an activity log entry, subsequent effective routing behavior—such as the actual next hop for internet-bound traffic—is not contained in this log.
When this WOULD be correct
You need to investigate who deleted a critical virtual network or changed a route table in your subscription. The subscription activity log would show the user, timestamp, and details of the management operation.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The AZ-104 exam frequently reuses these exact scenarios with slightly different constraints.
✓Effective routes for the network interfaceCorrect answer▾
Why this is correct
Effective routes for a network interface are the authoritative, data-plane view of the actual routing decisions applied to a VM's NIC. They combine Azure system routes, user-defined routes, and BGP routes, and display the selected next hop for each address prefix. To confirm that traffic from the app subnet to the internet uses a specific next hop (e.g., Internet, VPN gateway, or NVA), this blade shows the computed route that is actually used, not just a configured route table.
✗NSG flow logsWrong answer — click to see why▾
Why this is wrong here
NSG flow logs record traffic that passes through a network security group, but they do not show the effective route applied to a network interface. The question asks for the route being applied, not the traffic logs.
★ When this WOULD be the correct answer
When you need to analyze network traffic patterns, detect anomalies, or troubleshoot connectivity issues related to NSG rules, such as identifying denied or allowed traffic between VMs.
Why candidates choose this
Candidates may confuse NSG flow logs with route analysis because both involve network troubleshooting, but flow logs focus on traffic flows through NSGs, not routing decisions.
✗Azure Policy complianceWrong answer — click to see why▾
Why this is wrong here
Azure Policy compliance checks resource configurations against policies, but it does not show the actual applied routes for a network interface. The question asks for identifying which route is being applied, which requires effective routes, not policy compliance.
★ When this WOULD be the correct answer
An exam question asks: 'You need to ensure that all network interfaces in a subscription have a specific tag. Which Azure feature should you use to audit compliance?' In that case, Azure Policy compliance would be correct.
Why candidates choose this
Candidates may confuse Azure Policy with network troubleshooting tools, thinking policy can enforce or reveal routing behavior, when it only governs resource configurations.
✗The subscription activity logWrong answer — click to see why▾
Why this is wrong here
The subscription activity log tracks management-plane operations (e.g., creating or deleting resources), not data-plane routing decisions. It cannot show which route is applied to a specific network interface.
★ When this WOULD be the correct answer
You need to investigate who deleted a critical virtual network or changed a route table in your subscription. The subscription activity log would show the user, timestamp, and details of the management operation.
Why candidates choose this
Candidates may think the activity log records all network events, including routing, because it is a central auditing tool. They overlook that it only captures control-plane actions, not data-plane traffic paths.
Analysis generated from the official AZ-104blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Go deeper
Related to this question
Learn chapter
VPN Gateway and ExpressRoute
Key term
Subnet
A subnet is a logical subdivision of an IP network, created by partitioning a larger network address space using subnet masks.
Key term
User-defined route
A user-defined route (UDR) is a custom routing rule you create in a cloud or on-premises network to override or supplement the system's default routing behavior, directing network traffic along a specific path.
About these practice questions
One of 1,049 original AZ-104 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-104 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-104 exam.